Back to Blog
Blog67 min read

What Is a Managed Security Service Provider (MSSP)? Definition, Services, Pricing and the 35 Best MSSPs for 2026

A

Founder and Principal Security Consultant - CISSP, CEH, CHFI, Mandiant

What Is a Managed Security Service Provider (MSSP)? Definition, Services, Pricing and the 35 Best MSSPs for 2026

We have probably seen your problem before. Our smallest client had eight employees. Our largest secures the nuclear power plant of the United Arab Emirates. Whatever shape yours is, tell us about it and we will tell you how we would fix it.

Expert Guide and Rankings · October 2026

What Is a Managed Security Service Provider (MSSP)?

The definition, what an MSSP does hour by hour, how it differs from MDR, MSP and SOC-as-a-service, how providers price, what the contract must say about ownership and SLAs, and 35 providers ranked with honest trade-offs.

Disclosure: Atlant Security publishes this guide and appears in the ranking below, at the position we think we honestly belong, with the same card as every other provider. We say plainly which providers are the better call for situations we do not serve. Every other company is assessed from its own published material, public pricing where it exists, and the experience of evaluating providers for clients. No company paid for placement.

The short answer

A managed security service provider (MSSP) is a company that operates security controls and watches your systems for you, continuously, under a contract that defines what it monitors, what it may do when it finds something, and how it reports. You pay for analysts, a platform and a process you would otherwise have to staff around the clock. What stays your job: choosing what is watched, approving what the provider may do, fixing what it finds, and owning the risk.

Looking for the healthcare meaning? In US healthcare, MSSP stands for the Medicare Shared Savings Program, an accountable-care programme run by CMS. This guide is about the cybersecurity meaning.

A composite of calls we take every month: a company signed a three-year managed security contract because a customer's questionnaire asked for "24/7 monitoring". Eighteen months in, a finance laptop is encrypted on a Saturday night. The provider's portal shows the alert fired at 23:40 and an email went to a shared mailbox at 23:52. Nobody isolated the machine, because isolation was never in the contract; the service was "monitor and notify". By Monday the attacker had moved to the file server. The company had bought a feed of alerts and believed it had bought a security team.

That gap is what this guide is about. The market sells at least six different things under the label managed security, from telecoms running global SOCs to software vendors operating their own tool for you to a boutique that defines who does what and then does its share. The expensive mistake is buying the wrong kind, or the right kind without the response authority and the ownership map that make it work at 3 a.m.

So this is organised the way a buyer needs it: what a managed security service provider is and does, what is in the service catalogue and what stays with you, the taxonomy (MSSP, MDR, MSP, SOC-as-a-service, MXDR, vendor-operated), the five types of provider, how they price and what is missing from most quotes, what the contract must define, the first 90 days, how to switch, and 35 providers ranked with honest limitations.

Here are the 35 security companies we have evaluated for clients, competed against, or recommend when the requirement is wrong for us, with the detail you need to shortlist in an afternoon.

The Definition

What a Managed Security Service Provider Is (and Is Not)

A managed security service provider (MSSP) is a company you pay to operate security controls and watch your environment on your behalf, under a contract that defines what it monitors, when, what it may do when something is found, and how it reports. The service is continuous: it does not end with a report the way an audit or a penetration test does, and when you stop paying, the capability leaves with the provider.

The term dates from the late 1990s, when internet providers and telecoms began managing customers' firewalls and intrusion detection systems from central operations centres. The modern MSSP grew out of that: a security operations centre (SOC) staffed around the clock, connected to your log sources and security tools, following runbooks you have agreed, and escalating to named people in your organisation when a decision is yours to make.

In a working day the service runs a loop. Telemetry arrives from your endpoints, identity provider, email, network devices and cloud accounts. Detection content (rules, analytics, threat intelligence matches, hunts) turns it into alerts. An analyst acknowledges the alert, decides whether it is real and how severe, and either closes it, escalates it to you, or acts: isolating a device, disabling an account, blocking an address. A record is written, and at month end it becomes a report. Every one of those verbs can be in or out of your contract, which is why two "MSSPs" at the same price can deliver completely different outcomes.

What an MSSP is not:

  • An MSP (managed service provider) runs your IT: helpdesk, servers, Microsoft 365 administration. Many sell security as a bundle; few run a 24/7 SOC of their own.
  • A security product you buy and run yourself: an EDR agent, a SIEM licence, a firewall. The MSSP is the people operating such products.
  • An audit or a penetration test, which are point-in-time engagements that end with a document. The guide to information security audit services covers those.
  • Incident response on its own, which you call after the breach. Most MSSPs sell a retainer alongside monitoring; the retainer is a separate line with its own hours and authority.
  • A guarantee. No provider prevents every breach. What a good one guarantees is who is watching, how fast they act, and what they are allowed to do.

The Catalogue

What MSSPs Do: The Managed Security Service Catalogue

"Managed security" is a catalogue, and providers sell different pages of it. The table below lists the services you will see quoted, what the provider does under each, and what stays with your team no matter who you hire. The right-hand column is the one proposals leave out.

The managed security service catalogue: nine services with what the provider does and what stays with the customer
Figure 1. Nine services sold as managed security. Each comes with work that stays with you.
Service What the provider does What stays with you Pricing unit
24/7 security monitoring (managed SIEM, SOC-as-a-service) Collect logs from your sources, apply detection content, triage alerts around the clock, escalate by runbook Choosing and maintaining log sources, fixing what is found, deciding on risk Per log volume, per source, or tiered
Managed detection and response (MDR) Watch endpoint and identity telemetry, hunt, investigate, contain within an agreed authority (isolate, disable, block) Rebuilding systems, root cause, hardening, user communication Per endpoint or per user per month
Managed firewall, VPN and network security Operate the devices: rule changes, firmware, IDS/IPS signatures, VPN, sometimes SD-WAN Approving changes, network architecture, business justification for rules Per device or per site
Managed vulnerability management Scan on a schedule, deduplicate, prioritise by exploitability, report, sometimes open tickets Patching, configuration changes, exceptions Per asset or per IP
Managed email security Tune the gateway or the Microsoft 365 and Google Workspace filters, handle user reports, remove malicious mail Awareness training, policy, payment controls Per mailbox
Identity threat detection Watch sign-ins, MFA events, privilege changes and token anomalies in Entra ID, Okta or Google; disable accounts by runbook Joiner and leaver process, role design, HR events Per user
Cloud security posture monitoring Watch AWS, Azure, GCP and SaaS configuration drift, public exposure, key hygiene; alert and sometimes revert The architecture, the fix, the IaC pipeline Per account or per workload
Incident response retainer Reserved responders, pre-agreed access, playbooks, a hotline; often prepaid hours Authority to act, legal, insurer notification, communications Annual retainer plus hourly
Compliance and reporting Evidence packs, control status for SOC 2, ISO 27001, PCI DSS, HIPAA, NIS2 and DORA; audit support Owning the controls; the audit itself Bundled or per framework
Co-managed SOC Share the queue with your analysts: nights, weekends, surge, specialist skills Daytime tier 2, tuning decisions, ownership Per analyst tier or per hours
Virtual CISO and advisory Strategy, policy, board reporting, vendor management; sometimes bundled with monitoring Decisions and budget Monthly retainer

What an MSSP will not do, however much you pay:

  • See a source you never connected. Coverage is a list of log sources and agents; anything outside it is invisible, including the SaaS tool a department bought last month.
  • Fix what it finds. Patching, rebuilding, hardening and changing configuration stay with your team or your MSP unless you buy them as separate lines.
  • Own your risk. The provider recommends; someone in your company accepts, funds or declines, and signs the attestation your customers ask for.
  • Act beyond its authority. If the contract says notify, an analyst who sees ransomware staging at 2 a.m. sends an email. Write the authority you want.
  • Replace an incident response firm. Containment is in scope; forensics, legal privilege, insurer coordination and recovery are usually a retainer with another team.
  • Stop every attack. A good provider shortens the time between an attacker's first action and your first containment. It does not make the first action impossible.

Two services are sold under the same name with different meanings more often than the rest: "monitoring" (which may mean notify-only) and "response" (which may mean a phone call). Our managed security services site exists to settle those definitions before a proposal: platforms covered, who approves and implements, who may contain, during which hours, with what evidence.

The Taxonomy

MSSP vs MDR vs MSP vs SOC-as-a-Service vs MXDR

Six labels overlap in this market, and vendors move between them as fashions change. The differences that matter to a buyer are two: who owns the tools, and what the provider is allowed to do when it finds something.

Comparison matrix of MSSP, MDR, MSP, SOC-as-a-service, MXDR and vendor-operated services across promise, tools, response authority, fit and pricing unit
Figure 2. Six service models. Response authority and tool ownership are the rows that decide outcomes.
  • MSSP is the umbrella: a provider that monitors and manages security controls as a service. Historically device-centric (firewalls, IDS, SIEM); today most also sell MDR. The classic weakness is a contract that ends at "notify".
  • MDR (managed detection and response) narrows the scope to detection and response, usually on endpoint and identity telemetry, with containment by default inside agreed limits. The analyst isolates the machine; you rebuild it.
  • MSP (managed service provider) runs your IT. Security is a bundle on top, delivered through tools the MSP resells, often with monitoring subcontracted to an MDR vendor that serves MSPs (Huntress and Blackpoint Cyber are built for exactly this).
  • SOC-as-a-service rents you analysts and process, typically on your own SIEM and tools. The best fit for a company that owns a stack and lacks the night shift.
  • MXDR (managed extended detection and response) is MDR extended across endpoint, identity, email, cloud and network through a single platform, usually the provider's.
  • Vendor-operated services are the tool makers running their own tool for you: CrowdStrike Falcon Complete, Microsoft Defender Experts MDR, SentinelOne Wayfinder, Sophos MDR, Palo Alto Networks Unit 42 MDR. Excellent inside the platform; outside it, coverage is only as wide as the integration list, which runs from none to several hundred (Sophos and Zscaler now reach well beyond their own stacks).

The verdicts, in one table:

Verdict When it is true What to buy
You need MDR Your risk sits on endpoints and identities; you have nobody awake at night; you want containment without a phone call first A provider with authority to isolate and disable, written into the contract
You need a classic MSSP You own many controls (firewalls, VPN, IDS, a SIEM) and lack the people to operate and tune them Managed devices plus monitoring, with the response tier included
You need SOC-as-a-service You already own a SIEM and detection content and lack the shifts Analysts on your platform, your runbooks, your data
You need a vendor-operated service Your estate is standardised on one platform (Microsoft, CrowdStrike, SentinelOne, Sophos, Palo Alto Networks) The vendor's own team, plus a plan for what the platform cannot see
You need an MSP with a real SOC behind it Fewer than 100 people, no IT staff, everything in Microsoft 365 or Google Workspace A channel platform (Huntress, Blackpoint Cyber, Todyl) delivered by your IT provider, with the authority question answered
You need co-managed You have one to five security people who cannot cover 168 hours a week Night and weekend coverage on a platform you own, plus a responsibility map
You need an in-house SOC Regulation or scale demands it, and you can fund eight to twelve analysts plus engineering and a platform Usually still with a provider for surge, hunting and after-hours
You can run both An MSSP manages devices and compliance reporting while an MDR provider handles endpoint and identity response One responsibility map covering both, so no alert falls between them

Co-managed is the seventh word, and the most honest one for many mid-market companies: your people own the decisions and the daytime queue, a provider covers nights, weekends and specialist work, and a written map says who does what.

Before You Start

The Question Most Buyers Get Wrong

Most companies start their search asking: "Who is the best managed security service provider?"

That is the wrong question. Arctic Wolf is excellent for a 400-person company with a mixed estate and no security staff; a 40-person SaaS company on Microsoft 365 will pay for coverage it cannot use. CrowdStrike Falcon Complete is superb if every device runs Falcon; it will never see your Google Workspace. A telecom MSSP can watch a global network; it will send your 30-seat office a quarterly PDF.

The right question is: "What do we need watched, who acts when it fires, what are they allowed to do, and who owns the fix?"

Before Reading Further, Answer These:

  1. What triggered this? (A customer questionnaire, an insurer, a regulator, an incident, or an IT lead who cannot keep watching alerts at midnight)
  2. What must be watched? (Endpoints, identities, email, cloud accounts, network, SaaS, OT; list the sources by name)
  3. What may the provider do without asking? (Isolate a device, disable an account, block an IP, or only call you)
  4. Who owns the fix? (Your IT team, an MSP, the provider, or nobody yet)
  5. What is the realistic budget? (Under $3,000 a month, $3,000 to $15,000, or a programme above $15,000 a month)

Keep your answers in mind as you read. Each provider below is tagged with who it is right for, based on how it sells and delivers, with its own marketing set aside.

The Real Numbers

Honest Pricing & Fit Matrix

Most providers will only price on a call. The table shows, for the top 20, what kind of provider each one is, how it prices, whether it requires its own tools, whether containment is included or an add-on, and who it fits, so you know what you are walking into before the demos start.

Company Type Pricing Own stack required? Containment Best Fit
Arctic Wolf Security operations platform Quote, bundled subscriptions No (open XDR); own agent optional Included; warranty up to $3M on three-year bundles Mid-market with no security staff
Sophos MDR Vendor MDR, platform-agnostic Quote No, "bring your stack or use ours" Included; response modes offered, unnamed on the site Sophos estates first, then anyone
CrowdStrike Falcon Complete Vendor-operated MDR Quote (software bundles published) Yes, Falcon Included; 1-minute median time to contain claimed; warranty up to $2M Estates standardised on Falcon
Microsoft Defender Experts MDR Vendor-operated MDR Quote via Microsoft; 1,500 seats for Plan 2 Yes, Defender; Plan 2 adds Sentinel sources Managed with the Security Operator role, guided otherwise Microsoft 365 E5 and Defender estates
eSentire Pure-play MDR Published: $17 to $28 per user per month No (bring your own licences) or Atlas 15-minute mean time to contain claimed Mid-market and enterprise
Expel Pure-play MDR Quote, seat-based packages No, 160+ integrations Included with auto-remediation; 15-minute critical triage SLA Buyers who want transparency and SLAs
LevelBlue Global pure-play MSSP Quote No; own platforms available Included in MDR and MXDR; co-managed SOC options Enterprise and government
Atlant Security Boutique, co-managed Published: support from $1,500 a month No Defined per responsibility map; monitoring specified or overseen Firms of 20 to 500 on Microsoft 365 or Google Workspace
Orange Cyberdefense Telecom MSSP Quote No Included by contract; ANSSI-qualified operations European enterprise and critical infrastructure
Rapid7 MDR Vendor platform MDR Quote, per asset Yes, Command Platform, with third-party ingestion Included; unlimited IR; warranty in Ultimate Rapid7 customers, mid-market
SentinelOne Wayfinder MDR Vendor-operated MDR Quote (platform packages published) Yes, Singularity 60-minute SLA, 18-minute average claimed; $1M warranty Singularity estates
Zscaler MDR (formerly Red Canary) Vendor-owned MDR, open lineage Quote No, 200+ integrations; deepest inside Zscaler Automated response via ZIA, EDR isolation, IdP suspension Zscaler customers and former Red Canary clients
ReliaQuest Security operations platform Quote No, GreyMatter on your tools Under 5 minutes mean time to contain claimed Enterprises with their own tools and teams
Deepwatch BYO-SIEM MDR Quote No, runs on your SIEM Active Response included Enterprises that own a SIEM
Critical Start Vendor-agnostic MDR Quote, tiered No Contractual 60-minute MTTR North American mid-market and enterprise
Binary Defense Co-managed MDR and SIEM Quote No Per runbook on your tools Companies with a SIEM and a small team
Huntress SMB platform Published, from $8.99 per endpoint Yes, own agent SOC isolates and remediates SMBs and the MSPs that serve them
Blackpoint Cyber MSP-channel MDR Through MSPs Yes, own agent SOC responds, including account lockouts Companies buying through an MSP
Kroll MDR plus incident response Quote Moving to CrowdStrike Falcon Falcon Complete response after migration; ask Firms wanting MDR and IR from one provider
Mandiant Managed Defense Google SecOps MDR Quote Google SecOps plus supported tools Contains impacted hosts Enterprises on Google SecOps

* "Published" means a price is printed on the provider's own website; everything else is quoted after a call. "Own stack" means the service only runs on that vendor's agent or platform. Containment describes the default, as stated on the provider's site; every contract can change it.

Understanding the Landscape

The 5 Types of Managed Security Service Provider

Before you compare individual providers, understand which of five businesses you are shopping from. They hire differently, price differently and fail differently:

1. Telecom, Integrator and Full-Catalogue MSSPs

Operations centres across a region or several continents, hundreds of analysts, every service in the catalogue from managed firewalls to compliance reporting, and procurement built for enterprises. Strong where scale and geography matter. Weak where a 200-person company needs someone who knows its environment by name. You buy coverage and a brand your auditor recognises.

Examples: LevelBlue, Orange Cyberdefense, Verizon Business, NTT DATA, Accenture, IBM, Optiv, SecurityHQ, Integrity360, Cyderes

2. Pure-Play MDR and Security Operations Providers

Companies that exist to detect and respond, usually on a platform of their own plus your tools, with containment by default and published response-time claims. The most competitive segment of the market. You buy a response team and its metrics.

Examples: Arctic Wolf, eSentire, Expel, ReliaQuest, Deepwatch, Critical Start, Binary Defense, Kudelski Security

3. Vendor-Operated Managed Services

The maker of the tool runs it for you: deep in its own telemetry, fast inside its own platform, and only as wide as its integration list beyond it (CrowdStrike, Microsoft, Palo Alto Networks, Fortinet and Trend Micro stay inside their own stacks; Sophos and Zscaler now watch third-party tools too). The right choice when you have standardised on one vendor. You buy the vendor's own experts for the vendor's own product.

Examples: CrowdStrike Falcon Complete, Microsoft Defender Experts MDR, Sophos MDR, SentinelOne Wayfinder MDR, Rapid7 MDR, Palo Alto Networks Unit 42 MDR, Fortinet FortiGuard, Trend Micro, Zscaler MDR, Mandiant Managed Defense

4. SMB and MSP-Channel Platforms

Built for companies with fewer than a few hundred people, often sold through the IT provider you already use, priced per user or per endpoint, usually with a 24/7 SOC behind a simple product (check: Coro's site makes no such claim). You buy an outcome you can afford without a security team.

Examples: Huntress, Blackpoint Cyber, Field Effect, Coro, Todyl

5. Boutique and Co-Managed Services

Small firms that define the service with you, do the parts that need senior judgement, and arrange or oversee monitoring; none of them runs a thousand-seat SOC. You buy ownership and a named person.

Examples: Atlant Security, and the regional boutiques in your own market

Most mid-market companies end up with two of the five: an MDR or vendor-operated service for endpoints and identities, plus a boutique or an internal lead who owns the decisions and the map. The mistake is expecting one contract to cover both.

How We Ranked

Methodology for the 35 Providers

The 35 providers below were assessed on their own published material in October 2026: the services named on their sites, the response authority they describe, whether their service runs on their own platform or yours, published pricing where it exists, stated coverage and certifications, and corporate changes since 2024. We weighted fit for a defined buyer over size, and we say in each entry who the provider is wrong for. Ranks inside a tier are judgement; the tiers themselves (detailed reviews, specialists, the comparison table) reflect how often each provider belongs on a mid-market or enterprise shortlist. Atlant Security sits where our own criteria place a boutique that defines and co-manages services and does not run a thousand-seat SOC.

1

Security Operations Platform

Arctic Wolf

Arctic Wolf homepage

Arctic Wolf is the provider most mid-market buyers meet first, and for good reason: a Concierge Security Team assigned to your account, a 24/7 Triage Security Team, and a platform (Aurora, relaunched in March 2026 as an "agentic SOC") that plugs into the telemetry you already have through an open XDR architecture with more than 200 integrations. Founded in 2012 and based in Eden Prairie, Minnesota, it says more than 10,000 organisations rely on it, and its Inside the SOC page says critical events are detected and investigated within five minutes. It bought BlackBerry's Cylance endpoint business (closed February 2025, now Aurora Endpoint Security) and Sevco Security (February 2026), so it can now sell the agent as well as the watching.

The reality check: pricing is quoted as bundled subscriptions on one- or three-year terms, with no figures published. The Security Operations Warranty of up to $3 million applies only with Aurora Managed Endpoint Defense plus a security operations bundle on a three-year term; the bundle alone caps at $1.5 million. Read the warranty terms and the renewal clause with the same care as the SLA, and ask where your data is stored, since the site promises flexibility without naming SOC locations.

The Good

  • Named Concierge team plus a 24/7 triage team
  • Open XDR: works with the tools you own, 200+ integrations
  • Cloud, identity, endpoint and awareness training in one subscription
  • Deploys in as little as 10 days, per its site

The Limitations

  • Quote-only, bundled, with three-year terms behind the best warranty
  • Warranty conditions favour its own endpoint agent
  • No SOC locations or per-site headcount published
  • Very small estates get the same machine as large ones

Managed Services: Aurora MDR, Aurora Endpoint Security and managed endpoint defence, incident response and the Incident360 retainer, exposure management, cloud detection and response, cloud posture management, security awareness, Security Operations Warranty

Best For: Companies of 100 to 2,000 people with no security team of their own that want one provider watching everything and a named person to call.

2

Vendor MDR, Now Platform-Agnostic

Sophos MDR

Sophos MDR page

Sophos MDR describes itself as trusted by more than 40,000 organisations, and since Sophos completed the $859 million purchase of Secureworks in February 2025 it sells two services: Sophos MDR on its own Central platform, and Taegis MDR "powered by Secureworks" for customers who want the enterprise XDR stack. Both are open in the way that matters: "bring your stack or use ours", with more than 500 integrations, and nine regional security operations teams for global coverage. The MDR page claims 89 seconds from alert to automated response and that 52% of cases are resolved end to end by AI.

The reality check: prices and tier names are quoted on a call; the page mentions "flexible service tiers and response modes" without naming them. The Secureworks brand is effectively retired online (secureworks.com redirects to Sophos), so confirm which platform a quote is for and what the migration path is if you started on Taegis. Sophos has been owned by Thoma Bravo since 2020.

The Good

  • Two platforms, one provider: Sophos Central or Taegis
  • Works with third-party endpoint, firewall and cloud tools, 500+ integrations
  • Gartner Peer Insights Customers' Choice across endpoint, firewall and MDR, per its homepage
  • Managed Risk, incident response and a CISO Advantage service alongside

The Limitations

  • Tiers and response modes unnamed on the site
  • A post-acquisition workforce reduction and two product lines to reconcile
  • Best value when Sophos endpoint and firewall are already in place
  • Quote-only

Managed Services: Sophos MDR, Taegis MDR powered by Secureworks, Managed Risk (vulnerability management), incident response services, CISO Advantage

Best For: Organisations of any size already running Sophos products, and mid-market buyers who want a large MDR operation that will also watch the tools they already own.

3

Vendor-Operated MDR

CrowdStrike Falcon Complete

CrowdStrike Falcon Complete page

CrowdStrike Falcon Complete is the reference example of a tool maker running its own tool for you: CrowdStrike's analysts work inside the Falcon platform across endpoints, identities, cloud, SaaS and the AI agents it now monitors, with containment by default. The service page claims a one-minute median time to contain, a 75% reduction in mean time to respond, 2.7 million detections remediated a month, and warranty coverage of up to $2 million. Falcon software bundles are priced on the site (Falcon Go at $59.99, Pro at $99.99 and Enterprise at $184.99 per device per year, billed annually), while Falcon Complete itself is quoted.

The reality check: it only sees what Falcon sees. If Google Workspace, a third-party firewall or a SaaS application outside the Falcon integrations matters to you, that gap is yours to cover. Falcon Complete is also delivered through service providers (Kroll is moving its MDR onto it), which is worth knowing when a smaller MSSP quotes "CrowdStrike-powered" MDR. Platform certifications include ISO 27001, SOC 2 Type II and FedRAMP High; the warranty conditions are off the page.

The Good

  • The fastest containment claims in the market, inside its own platform
  • Identity, cloud and SaaS coverage from the same agent
  • Warranty of up to $2 million
  • FedRAMP High on the government platform

The Limitations

  • Requires the Falcon platform on every covered asset
  • Blind outside Falcon telemetry
  • MDR pricing, tiers and SLAs quoted only
  • Warranty terms live in the contract, off the page

Managed Services: Falcon Complete Next-Gen MDR across endpoint, identity, cloud, SaaS and AI agents, warranty-backed managed response, delivery through service-provider partners

Best For: Companies standardised on CrowdStrike Falcon that want the vendor's own team responding, directly or through an MSSP partner.

4

Vendor-Operated MDR for Microsoft Estates

Microsoft Defender Experts MDR

Microsoft Defender Experts page

Microsoft Defender Experts MDR, the service previously sold as Defender Experts for XDR, puts Microsoft's own analysts on your Defender incident queue around the clock. Plan 1 covers the Microsoft Defender workloads (endpoint, Office 365, identity, cloud apps) and includes Defender Experts Hunting; Plan 2 adds selected third-party sources through Microsoft Sentinel, expert-authored Sentinel content and a dedicated security delivery expert, with a minimum of 1,500 licensed seats. Response is "managed" when you grant the Security Operator role and "guided" when you grant Security Reader. Microsoft cites a Leader position in the 2026 IDC MarketScape for enterprise MDR and MXDR.

The reality check: no per-user price is published on the service page, the services overview, Microsoft Learn or the Product Terms (checked October 2026); you buy through your Microsoft account team, with servers billed as users. No response-time SLA is stated. The service is English-only, does not provide incident response for an active compromise, and runs in the commercial cloud only, so GCC High and DoD tenants are out. For an E5 estate with a small SOC it is the shortest path to managed response; for anything outside Defender it is a partial answer.

The Good

  • Microsoft's own analysts inside the Defender portal
  • Hunting and Ask Defender Experts included
  • Plan 2 brings Sentinel content and a named delivery expert
  • Operational data kept in the EU data boundary for EU customers

The Limitations

  • No published price or response-time SLA
  • 1,500-seat minimum for Plan 2 and the Suite
  • English-only; no active-incident response
  • Sees the Microsoft estate; third-party sources limited to eight through Sentinel

Managed Services: Defender Experts MDR Plan 1 and Plan 2, Defender Experts Hunting, Defender Experts for Servers, Defender Experts incident response (separate), Defender Experts Suite

Best For: Companies on Microsoft 365 E5 or the Defender suite with an overburdened or absent SOC, especially above 1,500 seats.

5

Pure-Play MDR, Published Pricing

eSentire

eSentire homepage

Waterloo, Ontario-based eSentire, founded in 2001 and majority-owned by Warburg Pincus, is one of the few MDR providers that prints its prices: on its online shop, Professional is $17, Enhanced $24 and Elite $28 per user per month (minimum ten users, billed annually), plus a $2,500-a-year launch and optimisation fee, with add-ons such as network detection and response at $6 per user. It says it protects more than 2,000 customers in over 80 countries, claims a 15-minute mean time to contain, and runs SOCs in Waterloo and Cork with a new US SOC in the Washington, D.C. area since July 2026 for US data residency. Bring your own licences (300+ integrations) or use its Atlas platform.

The reality check: the published tiers run from a ten-user minimum to 250 users, with larger estates quoted. Professional and Enhanced come with business-hours technical support; only Elite carries 24/7 technical support and 365-day log retention (Enhanced keeps 90 days). PCI compliance, SOC 2 and ISO 27001 are stated on its SOC page.

The Good

  • Published per-user pricing with the tier limits spelled out
  • Bring your own licences or use Atlas
  • 15-minute mean time to contain claimed; six-year average analyst tenure stated
  • US data residency option since 2026

The Limitations

  • $2,500 annual launch fee and a ten-user minimum
  • 24/7 technical support only in Elite
  • Published tiers stop at 250 users; larger estates are quoted
  • New chief executive in March 2026 and an AI startup acquired in September

Managed Services: MDR in Professional, Enhanced and Elite packages, digital forensics and incident response, Atlas Preempt exposure management and autonomous pentesting, Atlas SIEM, MDR for Microsoft, AWS cloud security, network and AI detection add-ons

Best For: Mid-market companies that want a known price per user before the call, and enterprises that want a large MDR operation on their own tools.

6

Pure-Play MDR, Transparent Operations

Expel

Expel homepage

Herndon, Virginia-based Expel built its reputation on showing customers the work: the Workbench platform exposes every investigation, and the SLA page publishes mean time to triage commitments of 15 minutes for critical, 30 for high and 180 for medium alerts, around the clock, with service credits for unscheduled Workbench downtime. The MDR page claims a 14-minute mean time to respond on critical and high incidents with auto-remediation. It is vendor-agnostic, with more than 160 integrations across endpoint, cloud (AWS, Azure, Google Cloud, OCI, Kubernetes), identity and SaaS, plus managed SIEM for your Sentinel or Splunk and, since August 2026, MDR for the AI attack surface. Forrester named it a Leader in its Q1 2025 MDR Wave.

The reality check: packages (Starter, Select, Premium) are priced by seat on request; unlimited integrations, API access and a dedicated engagement manager are Premium-only. Note what the SLA measures: triage is the analyst picking the alert up, and containment figures are published as averages, with no contractual guarantee.

The Good

  • Published triage SLAs by severity, with credits
  • Workbench shows every investigation as it happens
  • Works with what you own, 160+ integrations
  • Cloud and AI attack surface coverage

The Limitations

  • Seat-based pricing quoted only
  • Containment published as an average, with no guarantee
  • Premium tier gates API access and the engagement manager
  • Founding year and customer count unpublished

Managed Services: MDR (Starter, Select, Premium), managed SIEM for Microsoft Sentinel and Splunk, managed phishing, threat hunting, MDR for cloud infrastructure and the AI attack surface, auto-remediation

Best For: Companies that want to see the analysts' work and hold the provider to published triage times, on tools they already own.

7

Global Pure-Play MSSP

LevelBlue

LevelBlue homepage

LevelBlue launched in May 2024 as a standalone business formed from AT&T Cybersecurity (a joint venture of WillJam Ventures and AT&T) and has since absorbed Aon's cyber consulting groups including Stroz Friedberg (August 2025), Trustwave (19 August 2025), Cybereason (November 2025) and, by announcement in January 2026, the managed services of Fortra's Alert Logic. Its site calls it "the world's largest pure-play MSSP". The catalogue is the widest in this ranking: MDR and MXDR, co-managed SOC on Sentinel and other SIEMs, managed endpoint on the Cybereason platform, managed network and cloud security, email security, exposure management, penetration testing (2,000 a year, per its site), SpiderLabs threat intelligence and a resilience retainer with a 24/7 breach line. The Trustwave Government Fusion platform holds FedRAMP authorisation.

The reality check: five brands merged in about twenty months means several portals (USM Anywhere, Fusion, Nest, MailMarshal) and integration work still in progress; four SOCs were stated at launch and a Sydney SOC opened in August 2026, with the current total unpublished. Pricing is quoted. The scale is real, and so is the integration risk, so ask which platform and which team your contract lands on.

The Good

  • Every managed service under one contract, including testing and incident response
  • FedRAMP-authorised platform for the public sector
  • Works with your tools or its own platforms
  • Claims onboarding in as little as a few days

The Limitations

  • Five acquisitions since 2024; portals and teams still converging
  • Quote-only; SOC count unpublished since the mergers
  • Enterprise procurement for a mid-market buyer
  • Alert Logic deal announced, with no completion release on its site

Managed Services: MDR and MXDR, co-managed SOC, managed endpoint, managed network and cloud security, email security, exposure management, penetration testing, incident readiness and response retainer, cyber advisory, SpiderLabs threat intelligence

Best For: Enterprises and public-sector bodies that want one global MSSP for monitoring, managed devices, testing and response.

8

Boutique, Co-Managed, Defined Scope

Atlant Security

Atlant Security managed security services site

Atlant Security is our own firm, so read this entry with that in mind. The model is deliberately narrow: we define the managed service with you before anyone buys monitoring (which platforms are covered, who approves and implements changes, who triages which sources during which hours, who may suspend an account or isolate a device, and what evidence shows the work was done), then we do the parts that need senior judgement ourselves: Microsoft 365 and Entra ID or Google Workspace hardening, AWS, Azure and Google Cloud configuration work, an identity and endpoint programme, incident readiness and retainer terms, and virtual CISO leadership. Where 24/7 monitoring is needed, we specify it, procure or oversee it, and own the responsibility map, with monitoring coverage confirmed in the proposal as business hours, 24/7, or working alongside your existing SOC.

The reality check: we do not run a thousand-seat SOC, we do not sell a detection platform of our own, and a request for 24/7 coverage on our site is a requirement to evaluate, never an activated service. For a company that needs global coverage on a single vendor platform, or an enterprise programme across many regions, several providers above and below us in this ranking are the better call, and we say so on the scoping call. What we offer is a named person, a scope and price agreed in writing, month-to-month terms where the work is ongoing, and a service agreement you can read in one sitting.

The Good

  • A written responsibility map and service boundary before any monitoring is bought
  • The person on the scoping call does the work; no junior bench
  • Published starting prices: ongoing security support from $1,500 a month, Microsoft 365 and Entra ID audit from $1,450
  • Month to month where the work is ongoing; a free RFP builder that every bidder answers the same way

The Limitations

  • No 24/7 SOC or detection platform of our own; monitoring is specified, procured or overseen
  • Small team, limited parallel capacity
  • Enterprise multi-region programmes are out of scope
  • Lead times stretch in busy months

Managed Services: Managed security workstreams (Microsoft 365 and Entra ID, Google Workspace, AWS, Azure and Google Cloud, identity and endpoint, security monitoring and SOC operating model, incident response readiness and retainer, virtual CISO, assessment and compliance readiness), ongoing security support, 24/7 incident response

Best For: Companies of 20 to 500 people on Microsoft 365 or Google Workspace that need someone accountable for the controls, the customer questionnaires and the provider relationships, with monitoring bought as a defined service with named owners.

Rankings 9-20

The Next Tier: Strong Specialists

These providers are excellent in their niches. Choose by the shape of your estate and the authority you want to grant:

9. Orange Cyberdefense

Orange Cyberdefense homepage

Orange Cyberdefense, the cybersecurity unit of the Orange Group based in Paris La Défense, is the largest European MSSP in this ranking: 18 SOCs, 14 CyberSOCs and CERT teams, more than 3,000 employees and services in 160 countries. Its MDR integrates with your EDR, NDR and SIEM, cloud and OT systems, and it holds the French ANSSI qualifications (PASSI, PDIS, PRIS) alongside PCI QSA, CREST and SOC 2 Type II. It acquired the Swiss specialist ensec in July 2025 and entered Spain in May 2026.

Best for: European enterprises, critical infrastructure and anyone who needs ANSSI-qualified operations. Pricing: Quote-based.

10. Rapid7 MDR

Rapid7 MDR page

Boston-based Rapid7 MDR (11,500+ customers) sells MDR in Essentials, Advanced and Ultimate packages on its Command Platform, priced per endpoint, server and network, with the site stating that pricing is "not by data volume" and that Essentials includes 24/7 SOC monitoring, incident response, unlimited log ingestion and 13-month retention. Third-party ecosystem monitoring and a dedicated advisor arrive in Advanced and Ultimate, and a breach protection warranty in Ultimate, with no amount published. SOC 2 Type II, ISO 27001 and GovRAMP (June 2026); it acquired Kenzo Security in March 2026 and changed chief executive in June 2026.

Best for: Rapid7 customers and mid-market firms that want vulnerability management, SIEM and MDR from one vendor. Pricing: Quote, priced per asset.

11. SentinelOne Wayfinder MDR

SentinelOne Wayfinder MDR page

SentinelOne Wayfinder MDR is the service formerly reached at the Vigilance URLs, now branded Wayfinder MDR with Essentials and Elite tiers on the Singularity platform. The service page states a 3.3-minute average time to detect and a breach response warranty of up to $1 million; a July 2026 press release adds an 18-minute average mean time to respond against a 60-minute SLA, eight global delivery locations, FedRAMP High authorisation for Wayfinder and a Leader position in IDC's 2026 MarketScape for midmarket MDR. Singularity packages are priced on the site ($179.99 and $229.99 per endpoint per year); the MDR add-on is quoted.

Best for: Estates standardised on SentinelOne that want the vendor's own responders and a published SLA. Pricing: Quote for MDR; platform packages published.

12. Zscaler MDR (formerly Red Canary)

Zscaler Managed Detection and Response page

Zscaler MDR (formerly Red Canary) is Red Canary after its acquisition by Zscaler (agreement May 2025, completed 1 August 2025): redcanary.com now redirects to the Zscaler MDR page, and the service is sold as Zscaler Managed Detection & Response, with automated response through Zscaler Internet Access, EDR isolation and identity provider suspension. Red Canary served almost a thousand enterprises and integrated with more than 200 products, per its May 2025 announcement of the deal, a lineage Zscaler says continues. Pricing, tiers, SOC locations and the MDR-specific certification scope are missing from the page.

Best for: Zscaler customers, and former Red Canary clients deciding whether to stay through the integration. Pricing: Quote-based.

13. ReliaQuest

ReliaQuest homepage

Tampa-based ReliaQuest (founded 2007; more than $500 million raised at a $3.4 billion valuation in 2025; annual recurring revenue above $300 million) sells GreyMatter, a security operations platform that runs on your tools ("your security, your tools") from six global operating centres across Tampa, Las Vegas, Salt Lake City, Dublin, London and Pune. It claims containment in under five minutes (a 4.48-minute mean), a 22-minute mean time to investigate, a 48-minute mean time to resolve, and more than 1,000 customers. No security certifications are published on its site.

Best for: Enterprises with their own tools and analysts that want a platform-plus-service layer with aggressive containment metrics. Pricing: Quote-based.

14. Deepwatch

Deepwatch homepage

Palo Alto, California-based Deepwatch runs MDR on the SIEM you already own (Google SecOps, Splunk, Microsoft Sentinel, Securonix or CrowdStrike Next-Gen SIEM) through its Guardian platform, with Active Response (session revocation, password resets, host isolation) included in MDR, plus managed EDR, vulnerability management, dark web monitoring and managed firewall. It raised $180 million in February 2023, acquired Dassana in February 2025 and appointed a new chief executive in May 2026. SOC 2 Type II every year since it started, ISO 27001 since 2024, and a credit-backed SLA for 99.9% uptime and initial response, with the response minutes themselves kept off the public page.

Best for: Enterprises that own a SIEM and want response authority layered on it. Pricing: Quote-based.

15. Critical Start Highly Recommended

Critical Start homepage

Plano, Texas-based Critical Start is the rare provider that publishes a contractual SLA table: a 60-minute mean time to respond on every tier, a per-alert 60-minute commitment for critical and high alerts on its Signature tier, an optional 10-minute time to notify, and service credits when it misses. It is vendor-agnostic (no proprietary agents; CrowdStrike, Microsoft Defender, SentinelOne, Palo Alto Networks and others), runs a US-based 24/7 SOC, serves the US and Canada, is listed in Vista Equity Partners' portfolio, and holds ISO 27001 and SOC 2.

Best for: Mid-market and enterprise buyers in North America who want the SLA written into the contract. Pricing: Quote; three tiers (Essentials, Enterprise, Signature).

16. Binary Defense

Binary Defense homepage

Founded by David Kennedy (also the founder of TrustedSec) and based in Stow, Ohio, Binary Defense delivers vendor-agnostic MDR and co-managed SIEM on the tools you already run (Microsoft Defender and Sentinel, CrowdStrike, SentinelOne, Palo Alto Networks Cortex and others), with US-based operators around the clock, threat hunting, digital risk protection, and a NightBeacon platform your own SOC can license. In September 2025 it announced Dennis Hon as chief executive with a channel-first strategy, though its leadership page still lists founder David Kennedy as Founder and CEO. SOC 2 Type II; no response-time figures published.

Best for: Companies with a SIEM and a small team that want co-management and the option to take the platform in-house later. Pricing: Quote-based.

17. Huntress Highly Recommended

Huntress homepage

Columbia, Maryland-based Huntress has the clearest pricing in the market: Managed EDR at an MSRP of $8.99 per endpoint per month ($7.99 at 100 endpoints), managed identity threat detection for Microsoft 365 and Google Workspace at $4.80 per identity, managed SIEM at $4.00 per data source and security awareness training at $2.08 per learner, all backed by its 24/7 SOC and sold direct or through MSPs. It passed $250 million in annual recurring revenue and 270,000 businesses in July 2026. The service runs on its own agent alongside Microsoft Defender, on 12-month terms, with a 50-seat minimum through resellers.

Best for: Small and mid-sized businesses, and the MSPs that serve them, that want a priced, deployable managed service. Pricing: Published: Managed EDR from $8.99 per endpoint per month (MSRP).

18. Blackpoint Cyber

Blackpoint Cyber homepage

Blackpoint Cyber sells through MSP partners (its platform page counts more than 1,800 of them) and runs its own agent and 24/7 SOC, with threat hunters who respond on the partner's behalf, identity threat detection for Microsoft 365, Google Workspace and Cisco Duo, cloud posture, vulnerability management and a SIEM inside its CompassOne platform. It took $190 million from Bain Capital and Accel in 2023. Packages (Essentials, Core, Standard) are priced through the MSP; SOC 2 Type 2.

Best for: Companies that buy security through their IT provider and want a SOC that acts, including locking compromised Microsoft 365 accounts. Pricing: Through MSP partners; quote.

19. Kroll

Kroll cyber services page

Kroll pairs managed detection with one of the largest incident response practices in the world, and in December 2025 announced it is migrating its global MDR service, more than half a million endpoints, onto CrowdStrike Falcon Complete Next-Gen MDR. Its heritage Kroll Responder service ran on the tech-agnostic Redscan platform with a $1 million incident protection warranty for clients on that platform. Buyers signing now should ask which platform they are getting and what the warranty terms are after the migration.

Best for: Mid-market and enterprise companies that want MDR and an incident response retainer from the same firm, especially where insurers or litigation are involved. Pricing: Quote-based.

20. Mandiant Managed Defense (Google Cloud)

Mandiant Managed Defense page on Google Cloud

Mandiant Managed Defense (Google Cloud), part of Google Cloud since 2022, delivers 24/7 threat detection, investigation and response on the Google Security Operations platform, with Mandiant experts triaging alerts "within minutes" per its site, continual hunting mapped to MITRE ATT&CK, and containment of impacted hosts. Its datasheet lists supported third-party technologies including CrowdStrike, SentinelOne and Microsoft Defender; curated detections depend on your Google SecOps licence.

Best for: Enterprises on Google SecOps, or standardising on it, that want detection informed by Mandiant's incident response work. Pricing: Quote-based.

Complete Listings

Providers 21-35: The Full Comparison

Fifteen more providers worth a place on a shortlist, by segment and geography. Where a provider prints its prices we quote them; everywhere else the honest answer is that you will be quoted after a call.

# Provider Base Type Managed services Pricing Best For / Honest Take
21 Accenture Dublin Global integrator Managed security services through more than 40 cybersecurity centres in 22 countries (per its 2024 and 2025 press releases), managed XDR (MxDR for Government on Google SecOps with FedRAMP High authorisation, per an April 2025 release; commercial MxDR as a service with Verizon since March 2025), identity and access management as a service Quote 29,000 cybersecurity specialists stated in 2025; closed the CyberCX acquisition (Australia, about 1,400 people) in February 2026; there is no standalone managed-security product page, so the offer is shaped per engagement
22 IBM Armonk, New York Global integrator Threat detection and response services including MDR on the X-Force Protection Platform for mixed-vendor estates, 14 SOCs per its August 2026 announcement (13 named on its locations page), X-Force incident response, OT security, autonomous security operations Quote Sold its QRadar SaaS assets to Palo Alto Networks (closed September 2024) and now acts as a preferred MSSP for Cortex XSIAM migrations while still supporting on-premises QRadar; a Leader in the 2026 IDC MarketScape for enterprise MDR and MXDR
23 Verizon Business New York Telecom MSSP Advanced SOC services with 9 SOCs and follow-the-sun analysts, Verizon-managed SIEM and EDR, DDoS Shield, SASE management, incident response retainer Tiered by monthly alert volume; quote Its standalone MDR pages have been retired (the URLs now redirect to the security overview) and managed XDR is offered as a service with Accenture since March 2025; strong for public sector and large networks
24 NTT DATA Tokyo Global integrator and telecom Managed XDR on Palo Alto Networks Cortex XSIAM and autonomous SOC services on Splunk (both described on its global services site, services.global.ntt), managed EDR with remote isolation, DFIR, OT SOC and vehicle SOC Quote 49 SOCs and more than 7,500 cybersecurity professionals stated; two web properties (nttdata.com and services.global.ntt) describe the same services with different centre counts; buyers on other platforms should ask for the Splunk option or a co-managed SOC
25 Cyderes Kansas City, Missouri Identity-first MSSP Fully managed or co-managed MDR with 500+ integrations, identity governance, privileged access and identity threat detection, exposure management, Howler Cell threat hunting Quote Formed from Herjavec Group and Fishtech in 2022 and majority-owned by Apax; five 24/7 SOCs (Kansas City, Arkansas, Orlando, Reading, Bengaluru) and 800+ staff; SOC 2 across the five centres; no SLAs published
26 Optiv Leawood, Kansas Large integrator; managed services and staff augmentation Agentic Security Operations (formerly Optiv MDR, built on Google Security Operations with Wiz), co-managed SIEM, Cyber Fusion Center, managed vulnerability and privileged access services Quote Sold its consulting arm to Vobis Ventures in June 2026 and renamed its MDR in August 2026; about 6,000 clients on its homepage and a 3:1 client-to-analyst ratio on its Cyber Fusion Center page; a reseller model, so ask which tools the service assumes
27 Palo Alto Networks (Unit 42 MDR) Santa Clara, California Vendor-operated MDR Unit 42 MDR on Cortex XDR, Managed XSIAM, managed threat hunting, incident response retainer with SLA tiers from 24 hours down to 2 hours Quote; requires Cortex licensing Only for Cortex XDR or XSIAM estates; the retainer is platform-independent and, per its site, accepted by more than 50 cyber insurance carriers
28 Fortinet (FortiGuard MDR and SOC-as-a-Service) Sunnyvale, California Vendor-operated MDR plus multivendor SOCaaS FortiGuard MDR for FortiEDR and FortiXDR customers, SOC-as-a-Service with multivendor monitoring, Managed FortiGate firewall service, incident response and readiness services Quote via partners; per-device SKU for Managed FortiGate MDR serves Fortinet endpoint customers only; SOCaaS promises escalation in as little as 15 minutes with remediation guidance, so your team executes the fix; SOCs in North America, EMEA and APAC; ISO 27001 and SOC 2 stated
29 Trend Micro (TrendAI Vision One MDR) Tokyo Vendor-operated MDR MDR across email, endpoint, server, cloud workload and network telemetry from Trend products, sold inside Service One tiers; the Complete tier includes 40 incident response hours Quote, bundled with licensing Enterprise business rebranded TrendAI in March 2026, so product names on older proposals have changed; the longest certification list in this group (ISO 27001, SOC 2 Type II, FedRAMP for government editions); covers Trend telemetry only
30 Kudelski Security Cheseaux-sur-Lausanne, Switzerland, and Phoenix, Arizona Vendor-agnostic MDR MDR on Microsoft, CrowdStrike, Google SecOps, Splunk or Claroty estates through its FusionDetect platform, MDR for OT, threat hunting, 24/7 incident response retainer Quote Division of the listed Kudelski Group; Cyber Fusion Centers in Switzerland, Spain and the US; claims under 15 minutes mean time to respond on high-severity incidents; ISO 27001, 27017, 27018 and SOC 2 Type II
31 SecurityHQ London (Europe office), six regional offices Vendor-agnostic MSSP MDR with your SIEM or theirs, endpoint, network and data detection and response, digital forensics and incident response, firewall and email gateway administration, SASE, vulnerability management, CISO as a service Quote Private since 2003 (as Si Consult, rebranded 2020); six SOCs (Pune, Dubai, London, Riyadh, Australia, US); CREST, ISO 27001, SOC 2; a strong choice for Middle East and Asia delivery
32 Integrity360 Dublin European MSSP Aegis MDR, CyberFire MDR on its own platform with endpoint-based pricing, managed SIEM, EDR, XDR and NDR, managed firewall, Microsoft and Fortinet services, CREST incident response, PCI DSS services Quote; CyberFire MDR priced per endpoint, no figures SOCs in Dublin, Sofia, Stockholm, Rome, Madrid, Johannesburg and Cape Town (its homepage counts seven, its SOC page six); ten acquisitions since 2023 and a North American presence from January 2026; two MDR brands to choose between
33 Field Effect Ottawa SMB platform with a 24/7 SOC MDR in Endpoint, Core and Complete packages (endpoint, Microsoft 365 and Google Workspace, network), AI Detection and Response, incident response services Published: $5 to $25 per user per month, onboarding included Own agent and platform, sold direct and through MSPs; the lower tiers are sized for 25 users or fewer; its trust centre and blog cover its SOC 2 and ISO 27001 work
34 Coro Chicago (first listed office) SMB platform Managed services covering email, endpoint and SASE, with Coro analysts handling the alerts the platform does not resolve automatically Quote per user or device, through partners Over 3,000 organisations per its site; four packages (AI Complete, Essentials, Endpoint, Lite); its site makes no 24/7 SOC claim, so ask who watches at night
35 Todyl Denver MSP-channel platform MXDR on Todyl's own cloud SIEM and agent with a 24/7 SOC, identity threat detection, SASE, EDR, SOAR and GRC modules Quote through MSP partners Channel-only, so end customers cannot buy direct; a dedicated detection and response account manager with at least five years' experience; $50 million Series B in 2024

The Numbers

How MSSPs Price (and the Lines Missing From Most Quotes)

Managed security is quoted six ways, and the model tells you how the provider thinks about your estate. Per-endpoint pricing comes from companies built around an agent; per-log-volume pricing comes from SIEM operators; per-user pricing comes from platforms that bundle email, identity and devices for small companies. None is wrong. What matters is the lines that are missing.

Six MSSP pricing models with how each is counted and what to watch for, plus the ten lines most quotes leave out
Figure 3. How the quote is built, and the lines that appear after you sign.

What the market charges, by segment, with our estimates labelled as such (the only exact prices in this guide are the ones a provider prints on its own website, listed in the ranking):

Segment Typical range Pricing Basis
SMB platform with 24/7 SOC (per user or per endpoint) Low single digits to around $15 per user or endpoint per month, bundling EDR, identity and email Published by some providers; minimums apply Our estimate
Pure-play MDR, mid-market Roughly $8 to $25 per endpoint per month; annual contracts; servers and cloud workloads priced higher Quote Our estimate
Vendor-operated MDR Often similar per-endpoint rates on top of the platform licence you already pay Quote, with some published list prices Our estimate
Managed SIEM / SOC-as-a-service Priced on log volume: a few thousand dollars a month for a small estate to six figures a year for an enterprise Quote Our estimate
Enterprise programme (telecom or integrator) Six to seven figures a year across monitoring, managed devices, IR retainer and reporting Quote Our estimate
Co-managed or boutique arrangement Monthly retainers from the low thousands, scoped by platforms and hours; monitoring tooling priced separately Published by some, including Atlant Security See ranking

Third-party benchmarks are scarce, which is part of why MSSP pricing confuses buyers. The figures below are the ones we could trace to a named source; treat them as market colour, never as quotes.

Source Figure How to read it
MSSP Alert, citing the 2024 MSSP Benchmark Pricing report (January 2025) Average monthly price for basic services $45 per endpoint; premium services $73 per endpoint per month; top earners $200 per endpoint. 98% of surveyed MSSPs offer MDR. A survey of providers, so it describes what MSSPs charge on average, including small regional ones
Secureframe, "MSSPs vs In-House SOCs" guide (undated) MSSP per-device pricing "from $10 to $250 per device"; in-house SOC costs "from $1 million to $7 million annually", with SOC analyst salaries averaging $96,811 A compliance vendor's guide; wide ranges, but a rare public source that prices the in-house alternative
Our estimate, mid-market MDR $8 to $25 per endpoint per month on annual terms; servers and cloud workloads priced higher; platform licence sometimes on top From proposals we have reviewed for clients in 2025 and 2026
Our estimate, SMB platforms with a 24/7 SOC Low single digits to around $15 per user or endpoint per month, bundled with EDR, identity and email Published tiers from several channel platforms plus client quotes

Worked scenarios make the models comparable. Three estates, three monthly totals, using the ranges above and leaving out onboarding and the tools you still buy:

Estate Option A Option B Versus in-house
50 endpoints, 60 users, Microsoft 365, one cloud account SMB platform with SOC: $300 to $900 a month Mid-market MDR: $400 to $1,250 a month, minimum commitments often raise this In-house: impossible at this size; one security generalist costs more than the service
250 endpoints, 300 users, hybrid estate, two cloud accounts MDR: $2,000 to $6,250 a month Classic MSSP with managed firewalls and SIEM: $4,000 to $12,000 a month, driven by log volume and device count In-house 24/7 SOC: eight to twelve analysts plus a platform, a seven-figure annual commitment
1,000 endpoints, 1,200 users, multi-region, several cloud accounts MDR: $8,000 to $25,000 a month Enterprise MSSP programme: $15,000 to $60,000 a month across monitoring, devices, retainer and reporting In-house 24/7 SOC: payroll for twelve or more analysts and engineers, platform, training; the managed route is usually a third to a half of that

* Scenario totals are arithmetic on our estimated ranges, for comparison between models. Real proposals move with log volume, server counts, cloud workloads, hours of coverage and response authority. Minimum monthly commitments at many providers put a floor under the small-estate figures.

The ten lines to ask about before the price means anything:

  • Onboarding and integration fees, and whether tuning time is included or billed as professional services.
  • Whether the SIEM or XDR licence is included or passed through, and who owns it at exit.
  • Log ingestion limits and the overage rate; what happens when you add a source.
  • Whether "response" means containment or notification, and what the provider may do without calling you.
  • Incident response hours included, the hourly rate above them, and whether unused hours expire.
  • The tools you still have to buy: EDR agents, firewalls, email gateway, backup.
  • Weekend and holiday coverage, time zones, and whether night-shift analysts are the same team.
  • Contract length, renewal uplift, and the termination notice period.
  • Data residency, retention, and the export of logs, cases and detections when you leave.
  • What the monthly report contains and who on your side will read it.

The Contract

What the Contract Must Define: Ownership, SLAs and Exit

Hands holding a printed escalation runbook with a pen beside a phone on a desk lit by a lamp
The runbook is the contract at 3 a.m.

The difference between a managed service that works and one that forwards alerts is written down before signature, in three documents: a responsibility map, an SLA with separate clocks, and an exit plan. Providers that are good at this will produce all three unprompted. Providers that are bad at it will send a brochure.

The responsibility map. For each activity, who is accountable, who does the work, who is consulted, who is informed. The cells that matter most are containment (may the provider isolate a device or disable an account without calling you, and within which limits?) and remediation (who rebuilds, who patches, who closes the ticket). Fill the map in with the provider during the proposal and attach it to the contract.

A responsibility map for a managed security service with accountable, responsible, consulted and informed marks across customer, MSSP, tool vendor and incident response partner
Figure 4. The responsibility map. Empty cells are the incidents nobody owns.

The SLA. One "response time" in a proposal is almost always time to acknowledge: the minutes until a human opens the alert. Ask for separate commitments for acknowledgement, triage (a decision with a severity and an owner) and containment (the action), by severity, with the measurement method and the monthly report that proves it. A provider with authority to contain can commit to minutes; one that must call you can only commit to the call.

Timeline of a security event from occurrence to remediation with the five clocks a managed security SLA should define separately
Figure 5. Five clocks, defined separately. Containment is the one that protects you.

The exit plan. Agree at the start what leaves with you: raw logs and their format, case records, the detections tuned for your environment, the configuration of any device the provider managed, and credentials. Agree the notice period and the handover support. The service boundary checklist on our managed security site walks through these decisions, and the RFP builder turns them into a brief every bidder answers the same way.

Buyer Beware

Red Flags When Choosing a Managed Security Service Provider

After years of reading other providers' contracts during incidents and audits, these are the warning signs that should end the conversation:

  • "Monitoring" that ends at an email - If the runbook for a confirmed ransomware precursor is "notify the customer", you have bought a feed. Ask what the analyst is allowed to do and read the clause.
  • One response time, undefined - A single "15-minute response" is acknowledgement. Ask for triage and containment times by severity, with the measurement method.
  • No named people - You should know who leads your account, which team covers nights, and whether the night shift is the provider's own staff or a subcontractor on another continent.
  • Alerts with no tuning period - A service that goes live in a week and produces 400 alerts a day has moved its workload to you. Tuning takes weeks and should be priced and scheduled.
  • Log sources chosen by price - If the quote drops identity or cloud logs to hit a number, the service cannot see where modern attacks start.
  • The platform licence held by the provider - When the SIEM or XDR subscription is in the provider's name, your detections, history and data leave with the contract.
  • Three-year terms with silent renewal uplifts - The market changes yearly; a provider acquired twice in that period is a different company. Ask for annual terms or a change-of-control clause.
  • "We cover everything" with no catalogue - A provider that cannot show the catalogue line by line, with what stays with you, will discover the gaps during an incident.
  • Reselling the tools it recommends - A monitoring recommendation that always lands on the vendor the provider resells deserves a second opinion.
  • No escalation exercise before go-live - If the first time the escalation tree is tested is a real incident, assume it will fail there.

Due Diligence

Questions to Ask Before Signing

Twenty questions, grouped the way a request for proposal should be. Send the same list to every bidder and compare the answers side by side; the gaps between answers are the service.

Coverage and detection

  1. Which of our log sources and agents will you ingest on day one, which are extra, and what does the coverage report look like?
  2. Do you see Microsoft 365 or Google Workspace, our cloud accounts and our SaaS applications, or only endpoints?
  3. How is detection content built and tuned for our environment, and how long is the tuning period?
  4. What alert volume do you expect from us at day 30 and day 90, and who pays for the tuning?
  5. How do you detect a source that has gone silent?

Response and people

  1. What may your analysts do without calling us: isolate a device, disable an account, block an address, revoke sessions? Where is that written?
  2. What are your acknowledgement, triage and containment times by severity, how are they measured, and what happens when you miss them?
  3. Who covers nights, weekends and holidays, where are they, and are they your employees or a subcontractor?
  4. Who is our named lead, and who will we talk to during an incident?
  5. Can we run an escalation exercise before go-live and see the timings?

Reporting, compliance and data

  1. Can we see a redacted monthly report and a redacted incident case?
  2. Which frameworks does the reporting map to (SOC 2, ISO 27001, PCI DSS, HIPAA, NIS2, DORA), and will you talk to our auditor?
  3. Where is our data stored, who can access it, how long is it retained, and which subcontractors touch it?
  4. What certifications does your own operation hold (SOC 2 Type 2, ISO 27001, CREST or equivalent), and can we see the report?
  5. How do we export logs, cases and detections, in what format, and at what cost?

Commercial

  1. What is the pricing unit, what counts (servers, VMs, shared mailboxes, service accounts), and what are the minimums?
  2. Which licences are included, which are passed through, and whose name are they in?
  3. What is the onboarding fee, what does it include, and what is billed as professional services?
  4. What is the term, the notice period, the renewal uplift, and the change-of-control clause if you are acquired?
  5. What is included in incident response, what is the hourly rate above it, and do unused retainer hours expire?

Operations

The First 90 Days, and How to Switch MSSPs

A managed security service is bought in a week and proven in a quarter. The first 90 days decide whether you have a security team or an alert feed, and a competent provider will show you its onboarding plan with dates before you sign.

A 90-day MSSP onboarding plan in three phases: connect and baseline, tune and rehearse, prove and report
Figure 6. The first 90 days. Ask for the escalation exercise timing in writing.

Switching providers is more common than the market admits, because providers merge, get acquired and change their platforms. Done well it takes 60 to 90 days of overlap: the new provider connects sources and tunes while the old one still watches; the escalation exercise is run against the new provider before the old contract ends; logs and cases are exported in their native format; devices managed by the old provider are re-enrolled; credentials are rotated the day the old access is removed. Done badly it is a gap of weeks in which nobody is watching, which is the moment a provider's exit clause was written for.

  1. Give notice and fix the dates. Confirm the notice period, the end of service, and the handover support the old contract promises.
  2. Run both in parallel for 60 to 90 days. The new provider connects sources and tunes while the old one still watches; nobody is unwatched for a night.
  3. Export before you need it. Logs in native format, case history, the detections tuned for you, device configurations, runbooks.
  4. Re-point telemetry and re-enrol agents. Log forwarders, cloud integrations and endpoint agents move to the new platform in waves, with the coverage report as the checklist.
  5. Rotate every credential and key the old provider held on the day its access ends, including API keys in your cloud accounts and the identity provider.
  6. Re-baseline and rehearse. Run the escalation exercise against the new provider before the old contract ends, and compare the timings with the SLA.

Three facts make switching cheap or expensive: who holds the platform licence, whether your detections are portable, and whether your logs sit in a format another SIEM can read. Decide those at purchase.

Evidence

MSSPs, Compliance Frameworks and Cyber Insurance

A managed service produces evidence all year for the controls it operates, which is why auditors and insurers ask about it. It cannot evidence controls it does not run. The split by framework:

Framework What the provider can evidence What stays with you
SOC 2 Monitoring and logging (CC7), incident handling, vulnerability management evidence, change alerts Access reviews, change management approvals, governance, the audit itself
ISO/IEC 27001:2022 A 8.15 logging, A 8.16 monitoring, A 8.8 technical vulnerability management, incident records for A 5.24 to 5.28 The ISMS, risk treatment, internal audit, management review, certification
PCI DSS v4.0 Requirement 10 logging and monitoring, 11.3 scanning evidence, 12.10 incident response support Segmentation, 11.4 penetration testing, the ROC or SAQ
HIPAA Security Rule Audit controls (164.312(b)), security incident procedures, system activity review The risk analysis, workforce training, policies, business associate agreements
NIS2 Incident handling and the 24-hour early warning inputs, logging, vulnerability handling evidence under Article 21 Management accountability, supply chain measures, the notification itself
DORA ICT incident detection and classification inputs under Article 17, logging for Article 9, testing evidence The ICT risk framework, register of contractual arrangements, TLPT

Cyber insurers ask a narrower set of questions, and a managed service answers most of them with evidence attached: MFA everywhere, EDR on every endpoint with 24/7 monitoring, tested backups, privileged access controls, email filtering, an incident response plan with a retainer. A provider whose monthly report maps to the insurer's questionnaire saves a week at renewal.

For the audit side of this split, see information security audit services; for the procedures auditors use to test the controls above, security audit procedures.

Context

A Short History of MSSPs, and Where the Market Is Going

The service has four ages. In the late 1990s, internet providers and telecoms began managing customers' firewalls and intrusion detection systems from central operations centres, and the label MSSP was born. In the 2000s the SIEM made centralised log monitoring a product, and the classic MSSP became a SIEM operator that forwarded alerts. In the mid-2010s, managed detection and response emerged as a reaction to that model: endpoint telemetry, hunting, and analysts with authority to contain. Since 2020 the categories have merged, and since 2024 the vendors have too.

Consolidation matters to a buyer because the provider you sign with may be a different company at renewal. The moves since 2024 that changed names on proposals:

Date What happened What it means for buyers
May 2024 AT&T Cybersecurity became LevelBlue, a standalone joint venture of WillJam Ventures and AT&T The AT&T name on your contract now belongs to a different company
September 2024 Palo Alto Networks closed its purchase of IBM's QRadar SaaS assets; IBM became a preferred MSSP for Cortex XSIAM migrations and kept on-premises QRadar If your SIEM was QRadar on Cloud, your platform and your MSSP relationship both changed
February 2025 Sophos closed its $859 million purchase of Secureworks; Taegis MDR is now sold "powered by Secureworks" beside Sophos MDR, and secureworks.com redirects to Sophos Two MDR platforms from one provider; confirm which one a quote is for
February 2025 Arctic Wolf closed its purchase of BlackBerry's Cylance endpoint business, now Aurora Endpoint Security The watcher now also sells the agent; warranty terms favour it
February 2025 Deepwatch acquired Dassana, adding continuous threat exposure management to its MDR platform Exposure management arrives inside MDR contracts; check what the add-on costs
March 2025 Verizon Business and Accenture partnered to sell managed XDR, identity and cyber risk services as a service Verizon's own MDR pages were retired; ask whose SOC delivers the service
August 2025 Zscaler completed its acquisition of Red Canary; the product is now Zscaler Managed Detection & Response Red Canary contracts, portal and roadmap move to Zscaler
August 2025 LevelBlue completed the Trustwave acquisition (19 August) and Aon's cyber consulting groups including Stroz Friedberg (1 August); Cybereason followed in November 2025 and Alert Logic's managed services were announced in January 2026 Five brands and several portals under one name; ask which team and platform serve you
December 2025 Kroll announced the migration of its global MDR service, more than half a million endpoints, onto CrowdStrike Falcon Complete Kroll Responder customers change platform and agent; confirm the warranty terms
December 2025 Cyderes acquired Lucidum (entity intelligence), its third acquisition since 2024 An identity-first platform being assembled by acquisition; ask what is integrated today
2026 SentinelOne rebranded its MDR service from Vigilance to Wayfinder (the old URLs redirect); Microsoft renamed Defender Experts for XDR to Defender Experts MDR and added Plan 2 Same services, new names on renewals; Plan 2 carries a 1,500-seat minimum
February 2026 Accenture closed its acquisition of CyberCX, an Australian MDR and managed security provider of about 1,400 people Regional MSSPs are folding into global integrators; check which centre serves you
March 2026 Arctic Wolf launched the Aurora "agentic SOC" after acquiring Sevco Security in February Expect AI-triage claims in every renewal conversation; ask what humans still review
March 2026 Trend Micro rebranded its enterprise business as TrendAI; Trend Vision One became TrendAI Vision One Product names on proposals and renewals changed; the service did not
June 2026 Optiv sold its advisory, consulting and transformation business to Vobis Ventures, keeping managed services and staff augmentation in-house Optiv is now a managed services and resale company; consulting comes from a partner
August 2026 Optiv renamed Optiv MDR to Agentic Security Operations, built on Google Security Operations with Wiz Check which platform your contract assumes if you signed before the change
August 2026 Integrity360 acquired CyberIAM, its tenth acquisition since 2023, after Advantus360 (January 2026) opened North America Two MDR brands and a fast-growing estate; ask which SOC and platform will serve you

Where it is going: AI triage inside every platform, with the honest providers measuring what it closes correctly; pricing that moves from endpoint counts towards risk and coverage; and buyers who, after a decade of alerts forwarded at midnight, write response authority into the contract. The providers below are ranked on how well they serve that buyer today.

Bottom Line

Most companies need a managed service plus an owner. Here is what we typically recommend, with budgets as estimates:

Startup / Small Business (10-50 employees)

  • Monitoring and response: an SMB platform with a 24/7 SOC behind it (Huntress, Field Effect, Coro, Todyl), often through your IT provider
  • Identity and email: the Microsoft 365 or Google Workspace controls configured properly first; monitoring is cheaper when the tenant is hardened
  • Owner: a named person, internal or a boutique on a retainer, who reads the reports and makes the decisions (Atlant Security's ongoing support starts at $1,500 a month)
  • Budget: $1,500 to $5,000 a month

Mid-Market (50-500 employees)

  • Detection and response: a pure-play MDR with containment authority (Arctic Wolf, eSentire, Expel, Critical Start, Deepwatch) or the vendor-operated service for a standardised estate (CrowdStrike Falcon Complete, Microsoft Defender Experts for XDR, Sophos MDR, SentinelOne Wayfinder)
  • Cloud and SaaS: confirm the provider ingests AWS, Azure, Google Cloud and Workspace logs, or add posture monitoring
  • Response retainer: written into the same contract, with hours and authority
  • Owner: a security lead or a vCISO who holds the responsibility map
  • Budget: $5,000 to $30,000 a month

Enterprise (500+ employees)

  • Programme partner: a global MSSP or integrator for multi-region coverage and managed devices (LevelBlue, Orange Cyberdefense, Accenture, IBM, NTT DATA, Verizon, Optiv)
  • Response: an MDR or vendor-operated service on the endpoint estate, plus an IR retainer with a named responder firm (Kroll, Mandiant)
  • Co-managed SOC: your analysts by day, the provider by night, on a platform you own (ReliaQuest, Deepwatch, Binary Defense)
  • Owner: an internal security operations lead; the provider reports to them, never the other way round
  • Budget: $30,000 a month to seven figures a year

The best managed security service is the one whose containment authority, ownership map and exit plan you can recite. Price it after those three are written.

Managed Security Service Providers List: All 35 at a Glance

The complete list from this ranking, in order, with the kind of provider each one is. Use it as a shortlist, then read the detailed reviews above for pricing, pros and cons.

  1. Arctic Wolf Security operations platform
  2. Sophos MDR MDR, Sophos Central or Taegis
  3. CrowdStrike Falcon Complete Vendor-operated MDR
  4. Microsoft Defender Experts MDR Vendor-operated MDR
  5. eSentire Pure-play MDR, published pricing
  6. Expel Pure-play MDR
  7. LevelBlue Global pure-play MSSP
  8. Atlant Security Boutique, co-managed
  9. Orange Cyberdefense Telecom MSSP
  10. Rapid7 MDR Vendor platform MDR
  11. SentinelOne Wayfinder MDR Vendor-operated MDR
  12. Zscaler MDR (formerly Red Canary) Vendor-owned MDR
  13. ReliaQuest Security operations platform
  14. Deepwatch BYO-SIEM MDR
  15. Critical Start MDR with contractual SLAs
  16. Binary Defense Co-managed MDR and SIEM
  17. Huntress SMB platform, published pricing
  18. Blackpoint Cyber MSP-channel MDR
  19. Kroll MDR and incident response
  20. Mandiant Managed Defense Google SecOps MDR
  21. Accenture Global integrator
  22. IBM Global integrator
  23. Verizon Business Telecom MSSP
  24. NTT DATA Global integrator
  25. Cyderes Identity-first MSSP
  26. Optiv Integrator, managed services
  27. Palo Alto Networks Unit 42 MDR Vendor-operated MDR
  28. Fortinet FortiGuard MDR Vendor-operated
  29. Trend Micro Vision One MDR Vendor-operated MDR
  30. Kudelski Security Vendor-agnostic MDR
  31. SecurityHQ Vendor-agnostic MSSP
  32. Integrity360 European MSSP
  33. Field Effect SMB platform, published pricing
  34. Coro SMB platform
  35. Todyl MSP-channel platform

MSSP vs MDR: Which Do You Need?

If your risk lives on laptops, servers and identities, and you want someone to act when a credential is stolen at midnight, you need MDR, with containment authority written in. If you run many controls (firewalls, VPNs, IDS, a SIEM you own) and lack the people to operate them, you need an MSSP in the classic sense, and should insist that its monitoring tier includes response. Most mid-market buyers in 2026 are buying MDR and calling it an MSSP, which is fine as long as the contract says what the analyst may do.

Managed Security Service Provider Examples

Examples by type, from the ranking above: telecom and integrator MSSPs such as LevelBlue, Orange Cyberdefense, Verizon, NTT DATA, Accenture and IBM; pure-play MDR providers such as Arctic Wolf, eSentire, Expel, ReliaQuest, Deepwatch, Critical Start and Binary Defense; vendor-operated services such as CrowdStrike Falcon Complete, Microsoft Defender Experts for XDR, Sophos MDR, SentinelOne Wayfinder, Palo Alto Networks Unit 42 MDR and Trend Micro managed XDR; SMB and MSP-channel platforms such as Huntress, Blackpoint Cyber, Field Effect, Coro and Todyl; and boutique, co-managed services such as Atlant Security.

How Much Does a Managed Security Service Provider Cost?

For a small company, an SMB platform with a 24/7 SOC behind it runs from the low single digits to around $15 per user or endpoint per month, plus an owner on a retainer. Mid-market MDR runs roughly $8 to $25 per endpoint per month on annual terms, with servers and cloud workloads priced higher and the platform licence sometimes on top. Managed SIEM is priced on log volume and ranges from a few thousand dollars a month to six figures a year. Enterprise programmes run six to seven figures a year. These are our estimates; the published prices in this guide are listed in the ranking, and the ten lines missing from most quotes are listed in the pricing section above.

Do Small Businesses Need an MSSP?

A small business needs someone watching identities, email and endpoints around the clock, because that is where attacks on small companies start, and nobody on a ten-person team is awake at 3 a.m. It rarely needs a classic MSSP with managed firewalls and a SIEM. The practical answer is an SMB platform with a real SOC behind it, bought directly or through the IT provider, plus a named owner who hardens the Microsoft 365 or Google Workspace tenant first and reads the monthly report. Our small business cybersecurity cost guide places that inside the whole budget, and our affordable cybersecurity support service is the owner half of that pairing.

MSSPs for Microsoft 365 and Google Workspace

Most companies under 500 people run on one of two tenants, and the managed service has to see them. For Microsoft 365, the vendor-operated route is Defender Experts for XDR on the E5 or Defender licences, and most MDR providers ingest Entra ID and Defender telemetry natively. Google Workspace is covered far less evenly: ask any provider to show Workspace sign-in and Drive-sharing detections before you believe the brochure. In both cases the tenant should be hardened before monitoring starts; monitoring a misconfigured tenant is paying analysts to watch avoidable alerts.

MSSP vs In-House SOC: The Real Comparison

An in-house 24/7 SOC needs at least eight to twelve analysts to cover shifts, holidays and attrition, plus engineering for the platform and a manager, before any tooling: a seven-figure annual commitment that very few companies under 2,000 people sustain. The managed route buys the shifts and the platform for a fraction of that, and keeps the decisions, the tuning and the ownership in-house. The honest hybrid for most mid-market and many enterprise teams is co-managed: your analysts by day on a platform you own, the provider by night and at weekends, with a responsibility map that says who does what.

Managed Security Service Providers Near Me: Does Location Matter?

Monitoring is remote by nature, and the best provider for your stack may be on another continent. Location matters in three cases: managed devices that need hands on site, regulations that require analysts or data in a jurisdiction (common for public sector, finance under DORA, and some healthcare), and time zones, because a provider whose night shift is your working day will escalate to people who are asleep. Ask where the analysts sit, where the data is stored, and who answers the phone in your afternoon.

For adjacent decisions, the computer security companies ranking covers endpoint and network vendors, the penetration testing companies ranking covers the testing side, and proactive security monitoring explains what to monitor first.

Common Questions

Frequently Asked Questions

What is a managed security service provider (MSSP)?

A company you pay to operate security controls and monitor your environment continuously, under a contract that defines what it watches, when, what it may do when something is found, and how it reports. Classic MSSPs manage firewalls, intrusion detection and SIEM platforms; modern ones also sell managed detection and response, vulnerability management, email and identity protection, cloud posture monitoring and incident response retainers.

What does an MSSP do day to day?

It collects telemetry from your endpoints, identities, email, network and cloud; applies detection content; has analysts acknowledge and triage alerts around the clock; escalates to named people in your organisation; takes the containment actions the contract allows, such as isolating a device or disabling an account; and records everything into cases and monthly reports.

What is the difference between an MSSP and MDR?

MDR is a narrower service focused on detecting and responding to threats, usually on endpoint and identity telemetry, with containment by default inside agreed limits. MSSP is the broader category of managed security, historically centred on operating controls and monitoring, with response often an add-on. In practice most MDR providers call themselves MSSPs and most MSSPs now sell MDR; buy the contract clause, never the label.

What is the difference between an MSSP and an MSP?

An MSP runs your IT: helpdesk, servers, Microsoft 365 administration. An MSSP runs your security operations. Many MSPs sell security bundles and resell a 24/7 SOC from an MDR vendor that serves the channel; ask who you call at night and whether the MSP has the authority to act.

How much does an MSSP cost?

SMB platforms with a 24/7 SOC run from the low single digits to around $15 per user or endpoint per month; mid-market MDR runs roughly $8 to $25 per endpoint per month on annual terms; managed SIEM is priced on log volume from a few thousand dollars a month upward; enterprise programmes run six to seven figures a year. Those are our estimates. Onboarding, licence pass-through, log overages, response beyond notification and IR hours are the lines to ask about before comparing numbers.

What should an MSSP contract include?

A service catalogue line by line with what stays with you; a responsibility map that says who is accountable and who acts for log coverage, triage, escalation, containment and remediation; an SLA with separate acknowledgement, triage and containment times by severity and the measurement method; named people and coverage hours; data residency and retention; the report format; and an exit plan covering logs, cases, detections, device configuration and credentials.

What is a good MSSP response time?

Ask for three numbers, because one hides the other two. Acknowledgement of a critical alert within 15 minutes is common; a triage decision within 30 to 60 minutes is common; containment within minutes is possible only when the provider has authority to act and within hours when it must call you. Expel publishes a mean time to respond figure on its site; most providers quote acknowledgement only.

Does an MSSP replace an internal security team?

It replaces the shifts and often the platform. It does not replace ownership: someone inside the company has to choose the log sources, approve the containment authority, own remediation, read the reports and decide on risk. Companies without that person buy a boutique retainer or a vCISO alongside the monitoring service.

Can an MSSP help with SOC 2, ISO 27001, PCI DSS, HIPAA, NIS2 or DORA?

Yes, for the controls it operates: monitoring, logging, vulnerability management, incident handling and the evidence that those ran all year. It cannot own controls it does not operate, and auditors will still test your access reviews, change management and governance. Ask which frameworks the monthly report maps to and whether the provider will talk to your auditor.

How long does MSSP onboarding take?

Connecting sources and agents takes days to two weeks. Tuning detections to your environment and retiring noise takes four to six weeks. Proving the service against the SLA with an escalation exercise and a readable report takes the rest of the first quarter. A provider that promises full value in a week is describing a feed of untuned alerts.

How do we switch MSSPs without a coverage gap?

Overlap the providers for 60 to 90 days: the new one connects and tunes while the old one still watches; run the escalation exercise against the new provider before the old contract ends; export logs and cases in native formats; re-enrol any devices the old provider managed; rotate credentials the day the old access is removed. Switching is cheap when you hold the platform licence and your detections are portable.

What does MSSP mean in healthcare?

In US healthcare, MSSP is the Medicare Shared Savings Program, an accountable care organisation programme run by the Centers for Medicare and Medicaid Services; it has nothing to do with security. In cybersecurity, MSSP is a managed security service provider, the subject of this guide. Hospitals and health systems do buy cybersecurity MSSP services, usually with HIPAA reporting attached.

Is an MSSP the same as a SOC?

A SOC (security operations centre) is a function: the people, process and platform that monitor and respond. An MSSP is a provider that runs a SOC for many customers. SOC-as-a-service is the MSSP offering that rents you that function on your own tools. An in-house SOC is the same function staffed by your own employees.

What is the difference between a SIEM and an MSSP?

A SIEM is software that collects and correlates logs and raises alerts. An MSSP is a company that operates security for you, often using a SIEM as one of its tools. Buying a SIEM without people to tune it and watch it produces a bill and a queue; buying an MSSP without a SIEM, or with the provider's own platform, produces monitoring without the licence. MDR providers frequently replace the SIEM with their own platform for endpoint and identity telemetry.

What certifications should an MSSP hold?

For the operation itself: a SOC 2 Type 2 report or ISO/IEC 27001 certification covering the SOC, and in the UK CREST accreditation for SOC services. For the people: GIAC certifications such as GCIA and GCIH, and vendor certifications for the platforms they operate. Ask to see the SOC 2 report itself, and ask what the night shift holds.

How do MSSPs handle our data and privacy?

Your logs, alerts and cases are processed and stored on the provider's platform or yours, often in another jurisdiction. The contract should state where data is stored, who can access it, which subcontractors are involved, how long it is retained, how it is exported and how it is deleted. Under GDPR the provider is usually a processor and needs a data processing agreement; under DORA and NIS2 it is an ICT third-party provider with its own register entry.

Can we move from MDR to an MSSP, or the other way round?

Yes, and it is common after an acquisition or a platform change. Treat it as a switch: overlap the providers for 60 to 90 days, export logs and cases, re-point telemetry, rotate credentials, and rehearse escalation against the new provider before the old contract ends. The direction matters less than whether the new contract carries the response authority the old one lacked.

Is Atlant Security an MSSP?

Partly. We define managed security services with clients (platforms, ownership, onboarding, monitoring coverage and response authority), do the senior parts ourselves (tenant hardening, identity and endpoint programmes, incident readiness, virtual CISO work) and specify or oversee 24/7 monitoring; we do not run a thousand-seat SOC. For a company that needs a global SOC with its own platform, several providers above us in this ranking are the better call, and we say so.

Need Help Deciding?

Tell us what must be watched, who should act at 3 a.m. and who owns the fix. We will say which kind of provider fits, name the ones we would call if it were our estate, and define our own part in writing if the scope suits us.

Published: October 2026 · Author: Alexander Sverdlov, Atlant Security

This guide reflects our honest assessment of each provider from its own published material, public pricing where it exists, and our experience evaluating providers for clients. Price ranges by segment are estimates and will vary with scope, log volume and contract terms; the only exact prices quoted are those printed on providers' own websites. Atlant Security publishes this guide and is ranked in it; we have business relationships with some companies mentioned. No company paid for placement. Conduct your own due diligence and get written proposals before choosing a provider.

Related services from Atlant Security: Affordable Cybersecurity Support, Virtual CISO, 24/7 Incident Response, IT Security Audit. Book a discovery call to discuss your specific situation.

If your requirement is narrower than anything above, the directory of cybersecurity companies lets you filter the whole market by service and country.

Define the service before you buy it.

Our managed security services site turns your platforms, hours and response requirements into a brief every provider answers the same way: who owns each platform, how onboarding runs, what is monitored, who may contain, and what leaves with you at exit. Free to use, without an account.

Build the managed security brief
Alexander Sverdlov

Alexander Sverdlov

Founder of Atlant Security. CISSP, CEH, CHFI and Mandiant certified. Author of 2 information security books, cybersecurity speaker at the largest cybersecurity conferences in Asia and a United Nations conference panelist. Former Microsoft security consulting team member, external cybersecurity consultant at the Emirates Nuclear Energy Corporation.

Connect on LinkedIn